← All guides

WordPress: Don't permanently save comment IP

WordPress maintains a separate field for the IP address of the comment author in comments. If you don't need it for your own purposes, you shouldn't simply accept storage as an unchangeable basic property.

Requirements

Check beforehand whether moderation, spam filters or blacklists actually need the comment IP.

Comment IP is its own data field

The WordPress data structure knows comment_author_IP. Plugins, themes and moderation tools can evaluate this field. That's why it's not enough to just check analytics and web server logs.

Minimize before saving

WordPress provides filters for comment data. A data-saving adjustment should remove the IP before the permanent database entry or reduce it to a non-personal value, unless a mandatory function depends on it.

Check

Spam filters, blacklists and moderation plugins can use the comment IP. After making the change, create test comments and check the database, moderation view and spam filter.

Spam protection

If comment spam needs to be prevented, first use local procedures and Antispam Bee to save data check without permanently saving the comment IP.

Dismantling

If a moderation or blocking function absolutely requires the comment IP, only specifically reactivate the previous storage and then limit storage and access again.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑